Lush confirms cyber incident later described as a ransomware attack
- Organization
- Lush
- Exploit
- Ransomware
- Industry
- Retail
Lush, the privately owned British cosmetics retailer, posted a short notice on January 11, 2024 confirming it was responding to a cyber security incident. The company said the investigation was at an early stage, that it had taken immediate steps to secure and screen all systems in order to contain the incident and limit the impact on operations, and that it had informed the relevant authorities.
Lush declined at the time to say what had happened or whether any data had been taken. The Record reported that the company was working with external IT forensic specialists and that it was unclear which parts of an operation spanning 49 countries had been affected. Security practitioners quoted by Silicon Republic said the circumstances were consistent with a ransomware attack, though Lush had not confirmed one.
The company later published a fuller statement describing the incident as a ransomware attack that temporarily shut down some of its internal computer functions in the UK and Ireland. Lush said forensic investigators had confirmed that its retail shops and ecommerce operations were not affected and that no customer credit card details or customer information had been accessed. Customer care and inquiry functions were suspended for a period, creating a backlog, while staff worked with limited access to normal systems.
The Akira ransomware operation claimed responsibility on its leak site on January 26, 2024, alleging it had taken 110 GB of data including scans of employee passports. Lush did not confirm the attribution and said it was working with security specialists to validate the claims.